Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an authenticated user to perform server-side request forgery against internal services by bypassing protections in the Git repository import functionality.
Problem types
CWE-918: Server-Side Request Forgery (SSRF)
Product status
18.0 (semver) before 18.6.6
18.7 (semver) before 18.7.4
18.8 (semver) before 18.8.4
Credits
Thanks [yunus0x](https://hackerone.com/yunus0x) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/issues/578091 (GitLab Issue #578091)
hackerone.com/reports/3314987 (HackerOne Bug Bounty Report #3314987)
about.gitlab.com/...10/patch-release-gitlab-18-8-4-released/